relaylet.

Closed launch · by invitation

Keep your agent.
Know every request.

relaylet sits between your coding agent and the model provider. It forwards every byte unchanged and records every attempt honestly: what was sent, what it cost, and what is still unknown.

Works with the clients you already use: Codex (OpenAI Responses) and Claude Code (Anthropic Messages).

HOW IT WORKS

Byte-faithful

Your client's request and the provider's stream pass through unchanged. That includes the opaque reasoning state that tool loops depend on. Nothing is rewritten, no model is silently substituted, and nothing is retried behind your back.

Honest accounting

Every attempt is recorded and given one of three states. Settled means it was charged from provider-reported usage. Not charged means nothing was processed. Unresolved means it was sent but the outcome is unknown. Unknown is never shown as zero.

Hard limits

Credit for a request's worst-case cost is held before the request leaves. If you bring your own provider key, it is encrypted at rest. Keys are scoped, rate-limited and revocable, and each one is shown only once.

WHAT YOUR AGENT'S OWN COUNTER LEAVES OUT

A cut stream, a silent retry, and a smaller bill than the one you may get

In one qualification run the provider's stream was cut mid-response. Codex then retried the request on its own, with the same content in a different JSON key order. Its summary printed tokens used 23,234, which counts only the completed requests.

relaylet's record for the same session showed three upstream requests that may have been billed. One of them had unknown usage, and it was the attempt Codex had retried.

attempts 3 | forwarded 3 | client retries 1
upstream requests that may be billed: 3
  (usage reported 2, unknown 1)
- #2 the upstream stream ended abruptly after
  1530 bytes without a terminal event. The
  provider may still have processed and billed
  it; relaylet did not retry.
- #3 completed. It repeats attempt #2
  (same request content: a client retry).

Observed with the real Codex 0.160.0 client against relaylet's deterministic stand-in provider. No real model was involved.

EVIDENCE, NOT CLAIMS

Connection passport

Each client was run through eight scenarios: a two-turn tool loop, a cut stream, a rate limit, a request budget, the wrong model, the wrong key, and cancellation before the provider had sent anything. The table shows what was observed. The evidence level is stated plainly: real clients, scripted provider, not yet live.

Codex 0.160.0Claude Code 2.1.288
Scenarios passed8 / 88 / 8
Opaque reasoning state returned intactyes (encrypted_content)yes (thinking signature)
Rate limit (429)does not retryretries and recovers
Rejected key (401)5 retries11 attempts over ~3 minutes
Cancel before the provider respondsupstream closed in ~1 supstream closed in ~1 s
Identifiers sent to the providerinstallation, session, thread, turn ids; working directorydevice id, session id; local paths
Traffic outside the model pathchatgpt.com, ab.chatgpt.com, github.com, api.github.comnone observed with CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1

Claude Code sends CLAUDE.md files from every parent directory of where it is launched. Launch it from your project, not from a folder that holds private notes.

SECURITY

Built to be attacked

STATUS · 2026-10

What is live, and what is not

Live

This page, served as static files.

Not yet

The hosted gateway and the customer console are not open, and no payments are being taken. Reselling model access requires the providers' written permission. Until we have it, accounts will use your own provider key.